Rebasoft
Rebasoft is a UK-based, founder-owned cybersecurity software company that sells a single unified platform for agentless asset discovery, KEV-first vulnerability prioritisation, secure configuration validation, identity auditing and agentless NAC, sold to mid-market and enterprise customers and MSP partners across 50+ countries.
- Company typePrivate
- Founded2009
- HeadquartersTwyford, United Kingdom
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Rebasoft does
Rebasoft Limited is a UK-based, founder-owned cybersecurity software company founded in 2009 by Philip Harragan (CEO) and Steve Wilkinson (CTO), headquartered in Wokingham with engineering presence in Reading. The company has built and continuously evolved a single unified cyber security platform since inception, organised around one asset, service and identity data model rather than stitched together from acquisitions. The platform spans agentless asset and service discovery (covering network, cloud, container, virtualisation, mobile and SaaS environments), KEV-first vulnerability prioritisation, continuous secure configuration validation against CIS, CE+, STIG/DISA and other baselines, identity and access auditing across Active Directory, Entra ID and M365, agentless Network Access Control, and NetFlow-based traffic analysis. Deployment options include on-premises, private cloud and managed service delivery, with a 3-day stated time to first value.
Rebasoft monetises primarily through annual subscription licensing, sold directly to enterprise and government customers and indirectly via an MSP/MSSP partner program that builds recurring assurance services on the platform. The go-to-market combines consultative demo-led enterprise field sales (20-30 minute live-console walkthroughs) with a channel motion targeting Managed Service Providers. Named customers span financial services (London Stock Exchange, Mizuho), government (UK Department of Transport), technology (SAP, Dell, Sense), retail (Co-op, Roundy's), manufacturing (Huntsman), education (University of the Highlands and Islands) and international charities, with deployments sized from 20 to 200,000 users across 50+ countries. The company positions its differentiators around tool consolidation, business-service contextualisation of risk, continuous compliance evidence for auditors and cyber insurers, and complementary integrations with CrowdStrike, Microsoft, Palo Alto, ServiceNow, Vanta, Drata and major SIEMs.
The business operates with 1-10 employees, no external funding rounds disclosed, and remains owned and managed by its original founders, with Gerard Allison joining as Strategic Advisor to the Board in 2026 to support channel and partner expansion. Supported compliance frameworks include Cyber Essentials/Plus, ISO 27001, PCI DSS, NIST CSF, DISA STIG, NHS DSPT and DORA.
Rebasoft firmographics
Firmographics- Name
- Rebasoft
- Legal name
- Rebasoft Limited
- Website
- https://rebasoft.net
- Company type
- Private
- Founded year
- 2009
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Rebasoft is a UK-based, founder-owned cybersecurity software company that sells a single unified platform for agentless asset discovery, KEV-first vulnerability prioritisation, secure configuration validation, identity auditing and agentless NAC, sold to mid-market and enterprise customers and MSP partners across 50+ countries.
- Ownership category
- akta.pro rank
Rebasoft industry classification
Industry- Product category
- Cyber Security Software
- NAICS
- Software Publishers (5132)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Backup, Archiving & Ransomware-Resilient Data Protection (HDADAFAL)
Keywords
Where Rebasoft is headquartered
LocationHeadquarters
- HQ city
- Twyford
- HQ country
- United Kingdom
- HQ region
- Europe
Offices2 records
Markets served
Rebasoft business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Software Platform Subscription: Annual subscription licensing for the unified cyber security platform covering asset discovery, vulnerability management, secure configuration, user access/identity, and network operations. Deployment options include on-premises, private cloud, or managed service delivery.
- Managed Services via Partners: MSPs and MSSPs use Rebasoft as the foundation for delivering recurring managed services to their customers. Partners build multiple service lines (discovery, mapping, vulnerability management, secure configuration, compliance, traffic visibility, board reporting) from a single platform deployment.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Annual subscription with deployment flexibility |
Go-to-market motion2 records
Distribution channels4 records
Marketing channels4 records
Rebasoft product offering
Product offeringCore offering
Rebasoft sells a unified cyber security software platform that consolidates agentless asset discovery, business-service mapping, KEV-first vulnerability prioritization, continuous secure configuration validation, user access and identity auditing, and agentless network access control into a single deployment. The platform is sold as an annual subscription to mid-market and enterprise customers (20 to 200,000 users) and to MSP/MSSP partners who deliver managed cyber assurance services. It is also offered via on-premises, private cloud, or managed service delivery to support data residency and regulatory requirements.
Product overview
Rebasoft is a unified cyber security platform that consolidates asset discovery, vulnerability management, secure configuration, identity auditing, network operations, and business-service mapping into a single deployment. The core Rebasoft Platform serves as the foundation, with four integrated capability modules: Asset & Service Intelligence (agentless discovery), Vulnerability Management (KEV-first prioritization), Secure Configuration (continuous compliance measurement), and User Access & Identity (multi-directory auditing). Additional add-on modules include Microsoft 365 Posture and Network Operations & NAC. The platform supports specific compliance solutions including Cyber Essentials/CE+ and broader control frameworks (NIST, ISO 27001, PCI DSS, DORA). The MSP/MSSP program enables partners to deliver recurring assurance services. The platform was built organically since 2009 rather than acquired, ensuring vertical integration of all capabilities on a single data model.
Differentiator
Problem solved
Functional benefit
Products and services
- Asset & Service Intelligence Agentless asset discovery and business service mapping capability that automatically identifies network, cloud, mobile, container and SaaS assets and organises them by the business services they support. Sold to enterprises, regulated organisations and MSP/MSSP partners as part of the unified Rebasoft platform.
- Vulnerability Management Continuous vulnerability management capability that prioritises Known-Exploited Vulnerabilities from CISA first and ranks every vulnerability by the business service it threatens, combining CVE, CISA KEV, EPSS and vendor advisories. Sold to enterprises and regulated organisations as part of the unified platform.
- Secure Configuration Continuous secure configuration management that measures configuration posture daily against CIS Benchmarks, CE+, STIG/DISA and other frameworks and detects drift on the same day. Maps findings to Group Policy or Intune controls for remediation.
- User Access & Identity Identity audit capability covering Active Directory, Entra ID, Microsoft 365, Windows local administrators and Linux sudoers, providing continuous MFA evidence, dormant account detection and user inventory. Sold to enterprises and regulated organisations as part of the unified platform.
- Microsoft 365 Posture Read-only Microsoft 365 and Entra ID posture audit covering licence inventory and waste (typical 10-20%), MFA coverage, privileged roles (standing vs PIM), and Intune device compliance. Works on all Entra licence tiers from Free upwards and is sold as part of the unified platform.
- Cyber Essentials / CE+
Quantifiable outcome
- Discovers up to 34% more assets than current inventory
- +6 more outcomes
Companies that use Rebasoft
Customer profileNamed customers13 records
Segments9 records
Ideal customer profiles2 records
Rebasoft technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration27 records
AI capability3 records
Feature7 records
Rebasoft partnerships and signals
Strategic signalPartnerships
Ten partnerships are on record, tiered core and secondary.
- CrowdStrikecoreComplementary integration where CrowdStrike provides protection and response while Rebasoft adds independent asset assurance, service mapping, control validation, and audit-ready evidence across the broader estate.
- CynetcoreCynet provides unified XDR and MDR; Rebasoft validates the assets, controls, configurations and business services Cynet protects, enabling organisations to prove their environment is known, controlled and resilient.
- DratacoreDrata provides automated compliance monitoring; Rebasoft backs it with continuously validated asset, configuration and control evidence from the live environment.
- MicrosoftcoreMicrosoft delivers security across Defender, Sentinel, Intune, Entra and M365. Rebasoft adds continuous asset discovery, business-service context, configuration assurance and compliance evidence across the Microsoft ecosystem.
- Palo Alto NetworkscorePalo Alto provides NGFW, Prisma and Cortex controls. Rebasoft gives these tools the asset, service and configuration context needed to prioritise risk and prove controls are working everywhere.
- ServiceNowcoreServiceNow manages workflows via CMDB, ITSM, ITAM, Service Mapping, SecOps and Vulnerability Response. Rebasoft keeps these powered by trusted, continuously validated asset, service and control data.
- SophoscoreSophos provides endpoint and network protection. Rebasoft assures by extending discovery to the assets, services and controls that sit beyond agent coverage.
- VantacoreVanta provides compliance dashboards. Rebasoft makes compliance evidence more trustworthy with continuous discovery and control validation across assets and services Vanta reports on.
- SIEM Partners (Sentinel, Splunk, Elastic, QRadar, Exabeam, LogRhythm, Google SecOps)secondarySIEM integrations give Microsoft Sentinel, Splunk, Elastic, QRadar, Exabeam, LogRhythm and Google SecOps the asset context, risk prioritisation and control evidence they need.
- MSP/MSSP PartnerscoreManaged Service Providers and MSSPs use Rebasoft as a platform foundation for building multiple recurring services: discovery, mapping, vulnerability management, secure configuration, compliance & GRC, traffic visibility, and board reporting.
Scale indicators3 records
Recent moves6 records
Expansion highlights6 records
Rebasoft competitors and assessment
Company assessmentBroad incumbents
- Microsoft: Broad incumbent offering Defender, Sentinel, Intune, and Entra ID that overlap with Rebasoft's M365 posture, vulnerability, identity, and network modules. Microsoft is also a core integration partner, illustrating the dual partner-competitor dynamic.
- ServiceNow: Broad incumbent that competes via CMDB, ITAM, SecOps, Vulnerability Response, and Service Mapping modules. ServiceNow is both a major integration partner and a potential competitive threat to Rebasoft's CMDB-adjacent capabilities within ITSM-led enterprise environments.
- CrowdStrike: Broad incumbent with Falcon platform that includes asset inventory, vulnerability, and exposure management. CrowdStrike is a formal integration partner of Rebasoft but increasingly competes in the asset intelligence and exposure management category.
Direct peers
- Tanium: Directly competes in endpoint and asset management with real-time visibility, vulnerability, and configuration capabilities overlapping Rebasoft's secure configuration and continuous discovery modules, particularly in large enterprise environments.
- Axonius: Directly competes in cyber asset management and security asset intelligence, offering a similar agentless platform for asset discovery, vulnerability prioritisation, and control validation across on-premises, cloud, and SaaS environments. Axonius is the most comparable asset-centric platform to Rebasoft.
- Rapid7: Directly competes in vulnerability management and security operations with InsightVM and the broader Insight platform, addressing similar risk-based prioritisation and compliance use cases as Rebasoft.
- Armis: Directly competes in cyber asset management, particularly for IT, OT, IoT, and medical device environments. Armis Centrix provides continuous asset discovery and security posture management comparable to Rebasoft's agentless, scan-less approach.
- Qualys: Directly competes as a cloud-based vulnerability management, configuration assessment, and asset discovery platform. Qualys VMDR and CyberSecurity Asset Management overlap with Rebasoft's discovery, vulnerability, and configuration capabilities.
- Tenable: Directly competes in vulnerability management and continuous configuration assessment, with Nessus and Tenable One providing asset-centric risk prioritisation similar to Rebasoft's KEV-first vulnerability and configuration modules.
Emerging players
- JupiterOne: Emerging peer in cyber asset intelligence and security graph, with similar focus on continuous asset inventory, relationship mapping, and compliance evidence. A relevant emerging competitor to Rebasoft's asset and service intelligence module.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Rebasoft social profiles
Digital presenceRebasoft compliance and trust
Trust signalCompliance10 records
Rebasoft financial estimates
Financial estimateRevenue estimate
Valuation estimate
Rebasoft leadership team
Management profileNumber of profiles
Profiles3 records
Rebasoft funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Rebasoft M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Rebasoft
What does Rebasoft do?
Rebasoft sells a unified cyber security software platform that consolidates agentless asset discovery, business-service mapping, KEV-first vulnerability prioritization, continuous secure configuration validation, user access and identity auditing, and agentless network access control into a single deployment. The platform is sold as an annual subscription to mid-market and enterprise customers (20 to 200,000 users) and to MSP/MSSP partners who deliver managed cyber assurance services. It is also offered via on-premises, private cloud, or managed service delivery to support data residency and regulatory requirements.
Is Rebasoft a public or private company?
Rebasoft is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Rebasoft founded?
Rebasoft was founded in 2009. It employs 1 to 10 people.
Where is Rebasoft based?
Rebasoft is headquartered in Twyford, United Kingdom, in the Europe region.
How does Rebasoft make money?
Two revenue lines are on record. Software Platform Subscription is the primary driver. The others are managed Services via Partners.
Who are Rebasoft's main competitors?
Broad incumbents on record are Microsoft, ServiceNow and CrowdStrike. Direct peers are Tanium, Axonius, Rapid7, Armis, Qualys and Tenable. JupiterOne is listed as an emerging player.
Does Rebasoft have an API?
Yes. Open REST APIs ensure data access and integration with other platforms. The API is designed for scalability from small environments to organisations managing hundreds of thousands of assets.
What industry is Rebasoft in?
Rebasoft's product category is Cyber Security Software. Its primary akta.pro industry code is HDADAFAL, Backup, Archiving & Ransomware-Resilient Data Protection. Its NAICS code is 5132 and its SIC code is 7372.